RedAlpha is known for reconnaissance-driven cyberespionage operations targeting the Tibetan community in India.
Analyst brief
RedAlpha (also tracked as DeepCliff, Red Dev 3) is a threat actor conducting cyberespionage campaigns against the Tibetan community for at least two years. The group primarily targets the Tibetan community based in India, employing light reconnaissance and selective targeting. It utilizes diverse malicious tooling, with its activity discovered through a new malware sample aimed at this diaspora. Defenders should focus on detecting suspicious reconnaissance operations and multi-vector malware infections, especially within networks connected to the Tibetan community.
RedAlpha
DeepCliffRed Dev 3
unknown
Recorded Future’s Insikt Group has identified two new cyberespionage campaigns targeting the Tibetan Community over the past two years. The campaigns, which we are collectively naming RedAlpha, combine light reconnaissance, selective targeting, and diverse malicious tooling. We discovered this activity as the result of pivoting off of a new malware sample observed targeting the Tibetan community based in India.